Unicard Smart Ticketing Service
Solution for commercial ticketing and ENCTS concessionary management with smart ticketing. Includes a cloud-based Customer Management System (CMS), ITSO HOPS, cEMV Ticketing, AMS and Part11 Fulfilment, Account Based Ticketing, Payments, Customer Portal and App, Reporting, and Support. Delivered as cEMV deployment (tap-and-go ABT), HOPS deployment, HOPS migration or HOPS integration.
Features
- Passenger Management, Ticket Management, Travel Management, and Cardholder Management
- English National Concessionary Travel Scheme (ENCTS), Youth, Home to School
- Commercial Travel Scheme Retail, Tap and Go, Account Based Ticketing
- Full API access, data lake, and data source integration
- Managed customer registration / managed customer support
- Multi-token capable including ITSO, Barcode / QR ticketing, app, cEMV
- Account Based Ticketing, Fare Capping, Settlement and Reconciliation
- 24/7 support desk, debt recovery, fraud management
- ITSO certified, PCI compliant, EMV for Transit approved
- Hardware agnostic tap collection, payments orchestration, payments service processor
Benefits
- Fully integrated service for cost reduction and management overhead reduction
- Easy existing ITSO Migration / cEMV migration
- Future-proofed including artificial intelligence, MaaS, Check-in-Check-out
- Integrated payments processing, Account Based Ticketing, fares engine
- Low training requirements, easy interface, increased contact centre efficiency
- Solutions for Local Authorities, Transport Authorities, Private Operators, School Travel
- Multi-operator configurations, ITSO terminal configuration, iSAM managed service
- Supports transport ticketing, non-transport ticketing, leisure ticketing, parking, ferries, tolls
- Customer Relationship Management, Invoicing management, Transport reporting
- Integrated Data Lake, Data Warehouse, APIs, Reporting, and Monitoring
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
1 8 5 9 2 1 1 3 4 3 1 7 4 1 0
Contact
UNICARD LIMITED
Alex Sbardella
Telephone: 01202850810
Email: sales@unicard-uk.com
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Other
- Multi cloud support
- No
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Existing HOPS, EMV Backoffice, EMV Middleoffice, CMS, Portals, Ticket Retail or Collection services, and Transport Information apps
- Cloud deployment model
- Hybrid cloud
- Service constraints
- Planned maintenance, bug fixes, and new feature releases are carried out on a schedule published in advance and agreed with the customer
- System requirements
-
- Access to administrative functions is restricted to whitelisted IPs
- Server-to-server communications require a certificate to be installed
- Service can be accessed in up-to-date web browsers
User support
- Email or online ticketing support
- Yes
- Support response times
-
● Priority 1 Fault (Critical): Response within 1 business hour
● Priority 2 Fault (High): Response within 4 business hours
● Priority 3 Fault (Medium): Response within 6 business hours
● Priority 4 Fault (Low): Response within 8 business hours
● Service Request: Response within 8 business hours
Figures quoted for Silver tier support. Enhanced support packages with faster response times are available. Response times are the same at weekends/holidays if the appropriate add-on has been purchased. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- Our system offers 98% uptime, 24/7/365 web service desk availability to raise tickets, telephone support 8am-6pm Monday-Friday excluding holidays, and a nominated support or account manager for each customer. This support level is included in the cost; further support levels are available as paid extras.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
We usually hold a single “train the trainers” session, lasting half a day, at the buyer’s offices for all managers using the system (up to 20 people), comprising a guided presentation and live demo, followed by Q&A, for each area of the system. The training is usually led by a Support Analyst for the system and the Account Manager. User documentation is also provided following the training session, including a knowledgebase. Follow-up training and revised documentation, for example after a major new update, can be arranged as part of the support agreement.
Specific questions that users have raised following training, that can’t be answered by the buyer’s trainers, can be submitted as support tickets. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- Data can be extracted through the system APIs or can be provided in an industry-standard ITSO export format.
- End-of-contract process
- We will facilitate a reasonable migration of data to a new provider in industry-standard export formats defined by Unicard. Custom export formats, extra integration support for the new provider, or project management of the overall migration are available at extra cost as per rate card.
- Documentation accessibility standard
- WCAG 2.2 A
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Some administrative functions are still functional but not optimised for use on mobile devices. Users will need to zoom/scroll to use all parts of the page and touch zones may not be optimised.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The main service interface is provided through a web browser. A full API interface layer is also provided with WSDL and documentation.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- The system has undergone an audit for WCAG best practice but no specific testing with assistive technology has taken place.
- API
- Yes
- What users can and can't do using the API
- The majority of day-to-day management functionality and data access can be done using the API in a secure manner. API documentation is available under NDA to paying customers.
- API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- No
Scaling
- Independence of resources
- Services are hosted in an autoscaling AWS environment in accordance with AWS Well Architected Framework principles. Human resources are managed using a resource planning process.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Users can access a range of standardised reports on the data contained within the system as well as monthly service performance reports for the system itself (e.g. uptime). Data can also be imported into an external business intelligence tool.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
- Physical access control, complying with SSAE-18 / ISAE 3402
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
- Data can be exported through the system APIs. Some reporting data is available via email exports. Bulk and custom exports can be provided at extra cost.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- SQL Database Extract with Schema
- AWS Glue
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- SQL Database Extract with Schema
- AWS Glue
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
- We offer a 95% uptime guarantee. For each 1% of uptime under the 95% service level for any given month, a service credit of 0.2% of the contract value will be applied to the account. Extended availability up to 99.99% is available as a paid extra.
- Approach to resilience
- This information is sensitive, but we can make it available upon request.
- Outage reporting
- Users have access to a real-time service dashboard and are notified of major incidents via email alerts.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Access restrictions in management interfaces and support channels
- All users are required to have individual accounts, this ensures access to data is given based on job roles and security levels. The service team will at times require "superuser" access, however there are 2 separate accounts used to ensure that a superuser account is only used when required to minimalize risk. Only the service team can communicate with customers, access to the service desk from outside the support team is approved by the support manager, and these accounts can only read tickets and make internal comments. Access is removed on the day on an employee leaves.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- We operate a robust ISMS, governed by ISO27001 framework and security policies, which are reviewed and updated at least annually. Within the business there is a separation of duties between the information security officer and the data protection officer, providing an enhanced level of security governance. We operate a risk management committee, which meets every month to review any current or new risks. New starters are inducted in Unicards security policy and procedures and any changes to these are communicated to the wider company, with a link for them to access the changed policy.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- A secure configuration framework is part of our ISMS. We follow the AWS Well Architected Framework alongside tools such as AWS Config through continuous security scans to ensure that the solution remains secure. Any changes to the configuration, infrastructure, or application are only deployed following approval at an internal Change Advisory Board and are tracked via a Jira ticketing system throughout the lifespan. Unicard align our secure configuration practices with CIS Benchmarks, Cyber Essentials Plus, PCI DSS v4 and AWS Foundational Security Best Practices.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Risks are identified, assessed and impacted and mitigated in accordance with the requirements of PCI-DSS and ISO 27001:2013 and in cooperation with the buyer. We use Qualys for vulnerability scans to detect misconfigurations and continuous monitoring. Advanced Endpoint Protection (AEP) solutions, such as AWS GuardDuty, Microsoft Defender for Endpoint, and AWS Security Hub, are utilised to enhance detection and prevention capabilities. A Patch Management Standard enforces timely updates for software and systems in conjunction with AWS' O/S patching regime.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- We have a number of monitoring controls in place, from application level monitoring, through to infrastructure and network, as well as AWS tools. The firewalls and IDS system alert on any unusual network traffic or access attempts. We have automated log shipping, to allow server and system access to be protected and not deletable. Alerts are raised to the 24/7 support function and Unicard has a well structured emergency response team (ERT) that takes immediate control of any known or potential breaches.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Processes are based on the ITIL Framework and ISO 20000 certification. Incidents can be raised by the internal monitoring and support teams as a MI ticket or incidents raised by customers via the Service Desk or by phone. The process is run by the Incident Manager, who is responsible for communication between the teams updating customers via email on a regular basis. Upon resolution a MIR report is provided by email containing the summary of the issue, timeline of events, a detailed root cause analysis, mitigation plan, and long term fix plan.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- Prospective customers can access a generic version of our Customer Management System loaded with a test data set for a reasonable time.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- LRQA
- ISO/IEC 27001 accreditation date
- Wednesday 2 July 2025
- What the ISO/IEC 27001 doesn’t cover
- N/A
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- LRQA
- ISO 9001 accreditation date
- Thursday 12 June 2025
- What the ISO 9001 doesn’t cover
- N/A
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- Yes
- Who accredited the PCI DSS certification
- Self-Assessment
- PCI DSS accreditation date
- Monday 14 April 2025
- What the PCI DSS doesn’t cover
- Any systems not processing PCI data are not PCI-DSS certified.
- Cyber essentials
- No
- Cyber Essentials Alternative
- None of the criteria
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- A8015596-df48-4f20-8cb5-13b08001f223
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Volunteering opportunities for staff
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Advertising of supply chain opportunities openly and to ensure they are accessible to a diverse range of businesses, including advertising all subcontracting opportunities on Contracts Finder
-